Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
gemini[.]v947[.]eu[.]cc
gemini.v947.eu.cc — Неперевірений. Уособлення бренду: Gemini; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 3/91 (alphaMountain.ai, Gridinsoft, SOCRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: Gname.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies gemini.v947.eu.cc as a live brand impersonation domain masquerading as the legitimate cryptocurrency platform Gemini. The domain leverages visual and textual cues to deceive visitors into believing they are interacting with an official service, likely aiming to harvest credentials or seed phrases for unauthorized wallet access. No crypto-drainer kit artifacts (e.g., Etherscan contract links, drainer.js payloads) are currently cataloged in public threat feeds, suggesting this may be an early-stage or low-sophistication campaign.
This domain was flagged with the following technical indicators: VirusTotal detection score of 1 out of 95 engines as of the latest scan, registered via Gname.com Pte. Ltd., resolving to IP 188.114.97.3, created on October 13, 1997, secured with a Google Trust Services SSL certificate, and currently unblocked in Google Safe Browsing (GSB). Additional threat intelligence shows no inclusion in major blocklists, placing it at minimal immediate detection coverage despite active impersonation activity.
Currently, the domain remains active and under investigation with status marked as 'active' in the threat database. No takedown or blocking action has been confirmed at this time. Given the lack of detections and absence of known drainer payloads, the risk is classified as 'under_investigation'—however, users interacting with this domain risk credential theft or cryptocurrency loss. Security teams and users are advised to block gemini.v947.eu.cc at the network and endpoint levels and avoid accessing it via any means. Monitor for updates as this investigation progresses.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260408-13BDC1 Recipient: complaint@gname.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога